Overview
- A custom request‑for‑quote swap proxy run by TrustedVolumes was exploited on May 7, 2026, in an attack that initially drained about $5.87 million and that the company later said totalled roughly $6.7 million.
- Security firms Blockaid and Verichains traced the breach to the bespoke RFQ proxy and found concrete coding errors: a public function with no access control, an authorization check that validated the wrong address, and broken replay protection that let forged orders execute.
- The attacker converted stolen tokens into a consolidated holding reported at about 2,513 ETH and then returned 1,122 ETH on July 18 while retaining roughly the same dollar value as a self‑declared bounty.
- TrustedVolumes has invited talks about a vulnerability bounty but has not formally accepted any terms, and 1inch said its core aggregation contracts and standard user routes were not compromised.
- Investigators and security firms continue on‑chain tracing to recover remaining funds, and the dollar value of returned assets is lower than in May because ETH has fallen since the theft, which affects liquidity providers and victims seeking restitution.